MALICIOUS — 77665a47ef769a48bf8bf15b0355c2578bd190e6f8ad79e3da07b72bfa111106
MALICIOUS — 77665a47ef769a48bf8bf15b0355c2578bd190e6f8ad79e3da07b72bfa111106 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Cerbu family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
77665a47ef769a48bf8bf15b0355c2578bd190e6f8ad79e3da07b72bfa111106 - SHA-1:
d2f2ca4ccdccd50760225307d7fb5e07b2ffe246 - MD5:
060d9aa21d125f8425dcea61934b203a - imphash:
5ab4a5fa77f7cef108828b3d18928877 - ssdeep:
1536:dY3oRXGDBmCsUyE7r5ky252/JVI8AP56Rmh2oRO356D3XEBEfH:dYsiky25IVIb56Qh2o0p6D3XEWfH - TLSH:
T1693B19A8425BA332F1FAED756C219CDC9814B0AC5172616C9A07DA3FD0F5037D9B62E0 - Submitted as: 77665a47ef769a48bf8bf15b0355c2578bd190e6f8ad79e3da07b72bfa111106
- File type: pe · Size: 110592 bytes
- Verdict: malicious (95/100) · Family: Cerbu
Detections (4 of 52 engines)
- ClamAV (daily): Win.Malware.Cerbu-9886333-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Malware.Cerbu-9886333-0 (rule
Win.Malware.Cerbu-9886333-0) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
File paths
- F:\Office\Target\x64\ship\postc2r\x-none\msohtmed.pdb
More Cerbu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report